A Joint Certification Program certification (the DD Form 2345) establishes that your company is a qualified U.S. or Canadian contractor for unclassified export-controlled technical data. Access to DLA’s export-controlled drawings also requires DLA Enhanced Validation. Both applications use the JCP Portal, and DLA says the DEV application can be initiated alongside the JCP application. DEV approval still requires an approved DD Form 2345. HQ DLA decides whether to grant access.
If your package comes from a Navy or Army contracting office rather than DLA, the solicitation’s own access instructions govern and DEV may not apply. The controlled package access guide covers which route applies to which package.
This procedure addresses U.S. applicants. DLA’s banner says all entities need an assessment in SPRS, but the same page explicitly exempts some Canadian applicants and gives circumstance-dependent instructions. Canadian applicants should use that dedicated guidance and ask JCP to resolve any conflict.
The two side by side
| JCP certification (DD Form 2345) | DLA Enhanced Validation (DEV) | |
|---|---|---|
| What it is | The certification 32 CFR Part 250 describes for a “qualified U.S. contractor”, administered by the U.S./Canada Joint Certification Program Office (Canadian applicants follow separate instructions) | A DLA-specific validation “that goes beyond the standard JCP Certification” |
| What it grants | Standing as a qualified contractor for unclassified military technical data across DoD | Access to export-controlled data in DLA’s DIBBS and cFolders systems |
| Prerequisites DLA lists | For U.S. applicants: registered and physically located in the U.S.. Active SAM registration and CAGE. NIST SP 800-171 assessment uploaded to SPRS. Rules for protecting sensitive information under DFARS 252.204-7012. A named data custodian | An approved DD Form 2345 attached to the DEV application. A DIBBS account with cFolders enabled. A business need tied to a DLA solicitation, contract or approved R&D project. The export-control handling training certificate |
| Where you apply | JCP Portal (paper and emailed forms are no longer accepted) | JCP Portal; the application can run concurrently with the JCP application |
| Who reviews and approves | JCP Office | JCP Office review, then HQ DLA legal review, then a Trade Security Control assessment by the DLA controlling authority. HQ DLA grants access |
| Term | Five years. Renewal application at least 120 days before expiry | Three years, according to DLA’s current FAQ. An entity-information change requires a JCP revision |
| DLA’s lead-time guidance | Initiate at least 120 days before you need the certification | ”Processing times may vary based on the volume of applications received into the JCP Portal and the completeness of submitted documentation” |
The JCP program page and FAQ supply the application, term and approval details in this table. Reviewed September 13, 2026.
CMMC suspension context
As read on September 13, 2026, DLA’s JCP page carries a notice of the July 13 CMMC Phase II suspension and states that Phase I self-assessment requirements remain in place. Its older CMMC tab still contains future certification language. Read the pause guide and the current solicitation separately. A suspension headline does not establish your package’s access conditions.
The order of operations
- SAM and CAGE first. DLA says your SAM registration must not expire within 90 days of submitting the JCP application.
- NIST SP 800-171 self-assessment in SPRS. DLA’s JCP page carries this banner as of September 13, 2026: “all entities seeking JCP Certification must have a NIST SP 800 171 Assessment posted in SPRS. This requirement applies even if the organization has completed or begun a CMMC assessment.” The U.S. certification instructions add that the assessment is re-accomplished every three years.
- Name a data custodian. An employee at the certified CAGE location, with an alternate if you want one. DLA says not to name outside third parties or temporary personnel.
- Complete the JCP application in the portal with the export-control training certificate. The portal allows you to initiate a DEV application concurrently. Respond to analyst requests within 90 days or the application is cancelled.
- Open a DIBBS account and enable cFolders.
- Complete the DEV application with the approved DD Form 2345 attached. Starting the applications together does not remove that approval condition.
- Wait for HQ DLA’s decision. The JCP Office reviews, HQ DLA legal reviews, the TSC assessment runs, and access is granted or not by DLA.
Two things stand out in that list. The cyber prerequisite sits at step 2, under the JCP itself, before DLA’s own validation. And the custodian at step 3 is a revision trigger: DLA says a JCP revision must be initiated immediately when the primary or alternate custodian leaves.
Why the DD 2345 alone doesn’t open the drawings
DLA states its position plainly on the Export Control Data Access page. Suppliers requesting access to export-controlled technical data for a DLA solicitation, purchase order or contract must have the JCP certification, the DIBBS and cFolders accounts, a business need, and “an approved DLA-specific certification for access to export-controlled data.” Then: “Approval for access to DLA export-controlled technical data is rendered by the DLA and not the JCP Office.”
The reason DLA gives is Trade Security Control. The JCP certifies the company. DLA validates the request against the specific data it holds for the Military Services. Both are DLA offices, which is why the two get confused.
When the package requires JCP without DEV
Not every controlled package runs through cFolders. The Navy RFQ for Hellfire adapters issued 25 August 2026 required a current DD Form 2345 and a verified CMMC status, then delivered the drawings to the named data custodian through DoD SAFE. That instruction does not state a DEV requirement. Read the solicitation’s access paragraph before you apply for anything.
What this page doesn’t do
DLA and the JCP Office decide who gets access, and on what timeline. Deep Fathom doesn’t issue, renew or speed either certification, and this page isn’t a portal tutorial. DLA’s user guides are linked below and will stay current longer than any walkthrough here.
Where Deep Fathom fits
The NIST SP 800-171 assessment behind a U.S. JCP application is compliance work. Deep Fathom supports evidence management and CMMC/NIST SP 800-171 workflows. Your assessment owner maintains the scope, assessment record and SPRS submission. Bring that work to a platform evaluation to see which supported workflow applies.
Deep Fathom organizes the assessment evidence. DLA and the JCP Office decide access. Your company decides whether to pursue the work.
If the SPRS entry behind your JCP application is the open item, tell our team which assessment and deadline you’re working through. We’ll demonstrate the relevant Deep Fathom assessment and evidence workflow. Review bid requirements